CVE-2015-7808
24.11.2015, 20:59
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.Enginsight
Vendor | Product | Version |
---|---|---|
vbulletin | vbulletin | 5.0.0 |
vbulletin | vbulletin | 5.0.1 |
vbulletin | vbulletin | 5.0.2 |
vbulletin | vbulletin | 5.0.3 |
vbulletin | vbulletin | 5.0.4 |
vbulletin | vbulletin | 5.0.5 |
vbulletin | vbulletin | 5.1.0 |
vbulletin | vbulletin | 5.1.0:rc1 |
vbulletin | vbulletin | 5.1.1 |
vbulletin | vbulletin | 5.1.2 |
vbulletin | vbulletin | 5.1.2:beta1 |
vbulletin | vbulletin | 5.1.2:rc1 |
vbulletin | vbulletin | 5.1.2:rc2 |
vbulletin | vbulletin | 5.1.3 |
vbulletin | vbulletin | 5.1.3:alpha5 |
vbulletin | vbulletin | 5.1.4 |
vbulletin | vbulletin | 5.1.5 |
vbulletin | vbulletin | 5.1.6 |
vbulletin | vbulletin | 5.1.7 |
vbulletin | vbulletin | 5.1.8 |
vbulletin | vbulletin | 5.1.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References